cbcvebase.

Microsoft Excel Viewer vulnerabilities

65 known vulnerabilities affecting microsoft/excel_viewer.

Total CVEs
65
CISA KEV
4
actively exploited
Public exploits
11
Exploited in wild
10
Severity breakdown
CRITICAL40HIGH14MEDIUM11

Vulnerabilities

Page 3 of 4
CVE-2018-8577P3HIGHCVSS 7.8v2007-sp32018-11-14
CVE-2018-8577 [HIGH] CVE-2018-8577: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from CVE-2018-8574.
nvd
CVE-2017-8501P3HIGHCVSS 7.8v20072017-07-11
CVE-2017-8501 [HIGH] CWE-119 CVE-2017-8501: Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502.
nvd
CVE-2018-8432P3HIGHCVSS 7.8v2007-sp32018-10-10
CVE-2018-8432 [HIGH] CVE-2018-8432: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft Excel Viewer, Microsoft PowerPoint Viewer, Windows Server 2019, Windows
nvd
CVE-2007-3030P3HIGHCVSS 7.6v20032007-07-10
CVE-2007-3030 [HIGH] CVE-2007-3030: Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
nvd
CVE-2017-8631P3HIGHCVSS 7.8v20072017-09-13
CVE-2017-8631 [HIGH] CVE-2017-8631: A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Web App 2013 Service Pack
nvd
CVE-2018-8375P3HIGHCVSS 7.8v2007-sp32018-08-15
CVE-2018-8375 [HIGH] CVE-2018-8375: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8379.
nvd
CVE-2007-0215P3HIGHCVSS 7.6v20032007-05-08
CVE-2007-0215 [HIGH] CVE-2007-0215: Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
nvd
CVE-2006-2388P3CRITICALCVSS 9.3v20032006-07-13
CVE-2006-2388 [CRITICAL] CWE-94 CVE-2006-2388: Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code vi Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
nvd
CVE-2006-3877P3CRITICALCVSS 9.3v20032006-10-10
CVE-2006-3877 [CRITICAL] CVE-2006-3877: Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2 Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
nvd
CVE-2007-1214P3MEDIUMCVSS 6.8v20032007-05-08
CVE-2007-1214 [MEDIUM] CWE-119 CVE-2007-1214: Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted rem Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
nvd
CVE-2017-11878P3HIGHCVSS 7.8v20072017-11-15
CVE-2017-11878 [HIGH] CWE-119 CVE-2017-11878: Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Servi Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, and Microsoft Excel Viewer 2007 Service Pack 3 allow an attacker to run arbitrary code in the context of the current user by fai
nvd
CVE-2006-1302P3CRITICALCVSS 9.3v20032006-07-13
CVE-2006-1302 [CRITICAL] CWE-119 CVE-2006-1302: Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbit Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
nvd
CVE-2006-1306P3CRITICALCVSS 9.3v20032006-07-13
CVE-2006-1306 [CRITICAL] CWE-94 CVE-2006-1306: Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xl Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
nvd
CVE-2006-1304P3CRITICALCVSS 9.3v20032006-07-13
CVE-2006-1304 [CRITICAL] CWE-94 CVE-2006-1304: Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbit Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
nvd
CVE-2006-1308P3CRITICALCVSS 9.3v20032006-07-13
CVE-2006-1308 [CRITICAL] CWE-94 CVE-2006-1308: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to exe Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
nvd
CVE-2006-1309P3CRITICALCVSS 9.3v20032006-07-13
CVE-2006-1309 [CRITICAL] CWE-94 CVE-2006-1309: Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xl Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
nvd
CVE-2015-2378P4MEDIUMCVSS 6.9v20072015-07-14
CVE-2015-2378 [MEDIUM] CVE-2015-2378: Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 S Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Remote Code Execution Vulnerability."
nvd
CVE-2006-3867P4MEDIUMCVSS 5.1v20032006-10-10
CVE-2006-3867 [MEDIUM] CVE-2006-3867: Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
nvd
CVE-2006-3875P4MEDIUMCVSS 5.1v20032006-10-10
CVE-2006-3875 [MEDIUM] CVE-2006-3875: Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
nvd
CVE-2018-8378P4MEDIUMCVSS 5.5v2007-sp32018-08-15
CVE-2018-8378 [MEDIUM] CWE-125 CVE-2018-8378: An information disclosure vulnerability exists when Microsoft Office software reads out of bound mem An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microso
nvd